网络与信息安全学报 ›› 2021, Vol. 7 ›› Issue (1): 143-156.doi: 10.11959/j.issn.2096-109x.2021015

• 学术论文 • 上一篇    下一篇

融合宏观与微观的双层威胁分析模型

孙澄, 胡浩, 杨英杰, 张红旗   

  1. 信息工程大学,河南 郑州 450001
  • 修回日期:2020-10-07 出版日期:2021-02-15 发布日期:2021-02-01
  • 作者简介:孙澄(1991- ),男,江苏常州人,信息工程大学硕士生,主要研究方向为APT检测跟踪。
    胡浩(1989- ),男,安徽池州人,博士,信息工程大学讲师,主要研究方向为网络态势感知。
    杨英杰(1971- ),男,河南郑州人,博士,信息工程大学教授,主要研究方向为信息安全。
    张红旗(1962- ),男,河北遵化人,信息工程大学教授、博士生导师,主要研究方向为网络安全、移动目标防御、等级保护和信息安全管理。
  • 基金资助:
    国家自然科学基金(61902427)

Two-layer threat analysis model integrating macro and micro

Cheng SUN, Hao HU, Yingjie YANG, Hongqi ZHANG   

  1. Information Engineering University, Zhengzhou 450001, China
  • Revised:2020-10-07 Online:2021-02-15 Published:2021-02-01
  • Supported by:
    The National Natural ScienceFoundation of China(61902427)

摘要:

针对现有威胁分析模型无法兼顾高级安全威胁的宏观发展趋势及微观传播路径的问题,建立了一种双层威胁分析模型TL-TAM。模型上层刻画严重程度由低到高的威胁发展趋势,下层融合技术漏洞攻击、社会工程攻击及网络扫描攻击,刻画威胁传播路径。据此,提出了威胁预测分析算法。实验结果表明,模型能够对威胁传播进行多层面综合分析,并且克服了基于攻击图的威胁分析模型局限于技术漏洞攻击的缺陷,更加适用于高级安全威胁的动态跟踪分析。

关键词: 双层模型, 传播路径, 社会工程, 网络扫描

Abstract:

The existing threat analysis models failed to comprehensively analyze the propagation of advanced security threats integrating the threat development trend and propagation path.In order to solve the problem, a two-layer threat analysis model named TL-TAM was established.The upper layer of the model depicted the threat development trend.The lower layer depicted the threat propagation path considering social engineering and networks can.Based on the model, prediction algorithm of threat development was proposed.The experimental result shows that the model can comprehensively analyze the threat propagation at multiple levels, overcome the defect that the threat analysis model based on attack graph is limited to technical vulnerability attack, and is more suitable for dynamic tracking analysis of advanced security threats.

Key words: two-layer model, propagation path, social engineering, network scan

中图分类号: 

No Suggested Reading articles found!